onlyTrustedInfo.comonlyTrustedInfo.comonlyTrustedInfo.com
Font ResizerAa
  • News
  • Finance
  • Sports
  • Life
  • Entertainment
  • Tech
Reading: Apple’s Passwords app was vulnerable to phishing attacks for nearly three months after launch
Share
onlyTrustedInfo.comonlyTrustedInfo.com
Font ResizerAa
  • News
  • Finance
  • Sports
  • Life
  • Entertainment
  • Tech
Search
  • News
  • Finance
  • Sports
  • Life
  • Entertainment
  • Tech
  • Advertise
  • Advertise
© 2025 OnlyTrustedInfo.com . All Rights Reserved.
Tech

Apple’s Passwords app was vulnerable to phishing attacks for nearly three months after launch

Last updated: March 18, 2025 12:36 pm
OnlyTrustedInfo.com
Share
3 Min Read
Apple’s Passwords app was vulnerable to phishing attacks for nearly three months after launch
SHARE

Apple’s Passwords app was vulnerable to phishing attacks for nearly three months after launch

In iOS 18, Apple spun off its Keychain password management tool—previously only tucked away in Settings—into a standalone app called Passwords. It was the company’s first move at making credential management more convenient for users. It’s now been revealed that a serious HTTP bug left Passwords users vulnerable to phishing attacks for nearly three months, from the initial release of iOS 18 until the patch in iOS 18.2.

Security researchers at Mysk first discovered the flaw after noticing that their iPhone’s App Privacy Report showed Passwords had contacted a staggering 130 different websites over insecure HTTP traffic. This prompted the duo to investigate further, finding that not only was the app fetching account logos and icons over HTTP—it also defaulted to opening password reset pages using the unencrypted protocol. “This left the user vulnerable: an attacker with privileged network access could intercept the HTTP request and redirect the user to a phishing website,” Mysk told 9to5Mac.

Mysk demonstrates how a phishing attack could be carried out:

“We were surprised that Apple didn’t enforce HTTPS by default for such a sensitive app,” Mysk states. “Additionally, Apple should provide an option for security-conscious users to disable downloading icons completely. I don’t feel comfortable with my password manager constantly pinging each website I maintain a password for, even though the calls Passwords sends don’t contain any ID.”

Most modern websites nowadays allow unencrypted HTTP connections but automatically redirect them to HTTPS using a 301 redirect. It’s important to note that while the Passwords app before iOS 18.2 would make a request over HTTP, it would redirected to the secure HTTPS version. Under normal circumstances, this would be totally fine, as the password changes occur on an encrypted page, ensuring that credentials are not sent in plaintext.

However, it becomes a problem when the attacker is connected to the same network as the user (i.e. Starbucks, airport, or hotel Wi-Fi) and intercepts the initial HTTP request before it redirects. From here they could manipulate the traffic in a few ways. As seen in Mysk’s demo above, this includes modifying the request to redirect a phishing site that resembles Microsoft’s live.com page. The attacker can then easily gather credentials from the victims and even launch other attacks.

While this was quietly patched in December of last year, Apple only just disclosed it in the last 24 hours. The Passwords app now uses HTTPS by default for all connections, so ensure you’re running at least 18.2 on your devices! I wouldn’t be surprised if this news travels far under the radar. Share for awareness!

Follow Arin: Twitter/X, LinkedIn, Threads

FTC: We use income earning auto affiliate links. More.

You Might Also Like

Netflix shows start appearing in Apple TV app unified Watchlist

Exclusive-Stellantis shelves Level 3 driver-assistance program as it downscales software ambitions, sources say

Unearthing the Moon’s Ancient Secrets: How Artemis III Missions Will Transform Our Understanding of the South Pole-Aitken Basin

Perfectly shaped cosmic bubble in space baffles astronomers

Devin, the viral coding AI agent, gets a new pay-as-you-go plan

Share This Article
Facebook X Copy Link Print
Share
Previous Article Pebble founder launches casual and affordable Apple Watch alternative with 30-day battery and custom faces Pebble founder launches casual and affordable Apple Watch alternative with 30-day battery and custom faces
Next Article Stability AI’s new AI model turns photos into 3D scenes Stability AI’s new AI model turns photos into 3D scenes

Latest News

Tiger Woods’ Swiss Jet Landing: The Desperate Gamble for Privacy and Recovery After DUI Arrest
Tiger Woods’ Swiss Jet Landing: The Desperate Gamble for Privacy and Recovery After DUI Arrest
Entertainment April 5, 2026
Ashley Iaconetti’s Real Housewives of Rhode Island Shock: Why the Cast Distrusted Her Bachelor Fame
Ashley Iaconetti’s Real Housewives of Rhode Island Shock: Why the Cast Distrusted Her Bachelor Fame
Entertainment April 5, 2026
Bill Murray’s UConn Farewell: The Inside Story of Luke Murray’s Boston College Hire
Bill Murray’s UConn Farewell: The Inside Story of Luke Murray’s Boston College Hire
Entertainment April 5, 2026
Prince Harry’s Alpine Reunion: Skiing with Trudeau and Gu Echoes Diana’s Legacy
Entertainment April 5, 2026
//
  • About Us
  • Contact US
  • Privacy Policy
onlyTrustedInfo.comonlyTrustedInfo.com
© 2026 OnlyTrustedInfo.com . All Rights Reserved.